Improving Cyber Resilience Debate

Full Debate: Read Full Debate

Lord Wallace of Saltaire

Main Page: Lord Wallace of Saltaire (Liberal Democrat - Life peer)
Wednesday 21st May 2025

(1 day, 20 hours ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate
Baroness Anderson of Stoke-on-Trent Portrait Baroness Anderson of Stoke-on-Trent (Lab)
- View Speech - Hansard - - - Excerpts

I thank my noble friend for the question. He is absolutely right: there is a clear role here for the National Cyber Security Centre, both during an attack and afterwards, as it works with experts. My noble friend is right that I cannot comment on the details of the current attacks. I reassure noble Lords that the NCSC has a sector-specific trust group, where 60 CEOs from the retail sector have come together, both during the attack and afterwards, to make sure that best practice and information are shared in real time, so that other retail organisations can make sure that they are not subject to similar attacks.

Lord Wallace of Saltaire Portrait Lord Wallace of Saltaire (LD)
- View Speech - Hansard - -

My Lords, the Minister will be aware of the NAO report in January on government systems, which says that

“departments have significant gaps in their system controls that are fundamental to their cyber resilience. The resilience of the hundreds of ageing legacy IT systems that departments still use is likely to be worse”.

Accepting that the Government have inherited a legacy of years of underinvestment in Whitehall IT, and that the cost of successful cyberattacks is very high, does it not make sense to raise the level of investment in replacing some of these legacy systems as rapidly as possible?

Baroness Anderson of Stoke-on-Trent Portrait Baroness Anderson of Stoke-on-Trent (Lab)
- View Speech - Hansard - - - Excerpts

The noble Lord raises an important point. The NAO report was clear in its criticisms of our structures, and we accept every recommendation of the report. We are working our way through them, which is why we will be bringing forward a government cybersecurity strategy this year—building on the work of the previous Government—to make sure that we are fit for purpose. On the updating of IT, I have just lived through the updating of the printer system in the Cabinet Office. I would suggest that we take a bit of time with the next one.